When Hospitality Software is Too Hospitable (CVE-2026-21966, CVE-2026-21967)An XSS Filter Bypass and a Curious SSRF in Oracle Hospitality OPERA2026‑02‑135 minute readresearch web pentesting